CVE-2006-5885
NuStore 1.0 - SQL Injection via Products.asp SubCatagoryID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5885. PoCs published by ajann.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in NuStore 1.0 via the Products.asp page. It allows an attacker to extract sensitive information such as passwords from the database by manipulating the CategoryID and SubCatagoryID parameters.
Description
SQL injection vulnerability in Products.asp in NuStore 1.0 allows remote attackers to execute arbitrary SQL commands via the SubCatagoryID parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in NuStore 1.0 via the Products.asp page. It allows an attacker to extract sensitive information such as passwords from the database by manipulating the CategoryID and SubCatagoryID parameters.